/
Application detections

Application detections

Detects users downloading many files in a short amount of time via Slack. Adversaries may use existing, legitimate web services and applications to download files to avoid detection.

The time threshold and number of file threshold should be adjusted to suit the user environment.

Source table → app.slack.audit

Related content

app.slack
app.slack
More like this
Slack delivery methods
Slack delivery methods
More like this
Slack delivery methods
Slack delivery methods
More like this
Slack Sink
Slack Sink
More like this
Release 23 - Out-of-the-box alerts
Release 23 - Out-of-the-box alerts
More like this
Simple Each alert
Simple Each alert
More like this